subr_asan.c revision 1.15 1 /* $NetBSD: subr_asan.c,v 1.15 2019/10/04 06:27:42 maxv Exp $ */
2
3 /*
4 * Copyright (c) 2018-2019 The NetBSD Foundation, Inc.
5 * All rights reserved.
6 *
7 * This code is derived from software contributed to The NetBSD Foundation
8 * by Maxime Villard.
9 *
10 * Redistribution and use in source and binary forms, with or without
11 * modification, are permitted provided that the following conditions
12 * are met:
13 * 1. Redistributions of source code must retain the above copyright
14 * notice, this list of conditions and the following disclaimer.
15 * 2. Redistributions in binary form must reproduce the above copyright
16 * notice, this list of conditions and the following disclaimer in the
17 * documentation and/or other materials provided with the distribution.
18 *
19 * THIS SOFTWARE IS PROVIDED BY THE NETBSD FOUNDATION, INC. AND CONTRIBUTORS
20 * ``AS IS'' AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED
21 * TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
22 * PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE FOUNDATION OR CONTRIBUTORS
23 * BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
24 * CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
25 * SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS
26 * INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN
27 * CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
28 * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE
29 * POSSIBILITY OF SUCH DAMAGE.
30 */
31
32 #include <sys/cdefs.h>
33 __KERNEL_RCSID(0, "$NetBSD: subr_asan.c,v 1.15 2019/10/04 06:27:42 maxv Exp $");
34
35 #include <sys/param.h>
36 #include <sys/device.h>
37 #include <sys/kernel.h>
38 #include <sys/param.h>
39 #include <sys/conf.h>
40 #include <sys/systm.h>
41 #include <sys/types.h>
42 #include <sys/asan.h>
43
44 #include <uvm/uvm.h>
45
46 #ifdef KASAN_PANIC
47 #define REPORT panic
48 #else
49 #define REPORT printf
50 #endif
51
52 /* ASAN constants. Part of the compiler ABI. */
53 #define KASAN_SHADOW_SCALE_SHIFT 3
54 #define KASAN_SHADOW_SCALE_SIZE (1UL << KASAN_SHADOW_SCALE_SHIFT)
55 #define KASAN_SHADOW_MASK (KASAN_SHADOW_SCALE_SIZE - 1)
56
57 /* The MD code. */
58 #include <machine/asan.h>
59
60 /* ASAN ABI version. */
61 #if defined(__clang__) && (__clang_major__ - 0 >= 6)
62 #define ASAN_ABI_VERSION 8
63 #elif __GNUC_PREREQ__(7, 1) && !defined(__clang__)
64 #define ASAN_ABI_VERSION 8
65 #elif __GNUC_PREREQ__(6, 1) && !defined(__clang__)
66 #define ASAN_ABI_VERSION 6
67 #else
68 #error "Unsupported compiler version"
69 #endif
70
71 #define __RET_ADDR (unsigned long)__builtin_return_address(0)
72
73 /* Global variable descriptor. Part of the compiler ABI. */
74 struct __asan_global_source_location {
75 const char *filename;
76 int line_no;
77 int column_no;
78 };
79 struct __asan_global {
80 const void *beg; /* address of the global variable */
81 size_t size; /* size of the global variable */
82 size_t size_with_redzone; /* size with the redzone */
83 const void *name; /* name of the variable */
84 const void *module_name; /* name of the module where the var is declared */
85 unsigned long has_dynamic_init; /* the var has dyn initializer (c++) */
86 struct __asan_global_source_location *location;
87 #if ASAN_ABI_VERSION >= 7
88 uintptr_t odr_indicator; /* the address of the ODR indicator symbol */
89 #endif
90 };
91
92 static bool kasan_enabled __read_mostly = false;
93
94 /* -------------------------------------------------------------------------- */
95
96 void
97 kasan_shadow_map(void *addr, size_t size)
98 {
99 size_t sz, npages, i;
100 vaddr_t sva, eva;
101
102 KASSERT((vaddr_t)addr % KASAN_SHADOW_SCALE_SIZE == 0);
103
104 sz = roundup(size, KASAN_SHADOW_SCALE_SIZE) / KASAN_SHADOW_SCALE_SIZE;
105
106 sva = (vaddr_t)kasan_md_addr_to_shad(addr);
107 eva = (vaddr_t)kasan_md_addr_to_shad(addr) + sz;
108
109 sva = rounddown(sva, PAGE_SIZE);
110 eva = roundup(eva, PAGE_SIZE);
111
112 npages = (eva - sva) / PAGE_SIZE;
113
114 KASSERT(sva >= KASAN_MD_SHADOW_START && eva < KASAN_MD_SHADOW_END);
115
116 for (i = 0; i < npages; i++) {
117 kasan_md_shadow_map_page(sva + i * PAGE_SIZE);
118 }
119 }
120
121 static void
122 kasan_ctors(void)
123 {
124 extern uint64_t __CTOR_LIST__, __CTOR_END__;
125 size_t nentries, i;
126 uint64_t *ptr;
127
128 nentries = ((size_t)&__CTOR_END__ - (size_t)&__CTOR_LIST__) /
129 sizeof(uintptr_t);
130
131 ptr = &__CTOR_LIST__;
132 for (i = 0; i < nentries; i++) {
133 void (*func)(void);
134
135 func = (void *)(*ptr);
136 (*func)();
137
138 ptr++;
139 }
140 }
141
142 void
143 kasan_early_init(void *stack)
144 {
145 kasan_md_early_init(stack);
146 }
147
148 void
149 kasan_init(void)
150 {
151 /* MD initialization. */
152 kasan_md_init();
153
154 /* Now officially enabled. */
155 kasan_enabled = true;
156
157 /* Call the ASAN constructors. */
158 kasan_ctors();
159 }
160
161 static inline const char *
162 kasan_code_name(uint8_t code)
163 {
164 switch (code) {
165 case KASAN_GENERIC_REDZONE:
166 return "GenericRedZone";
167 case KASAN_MALLOC_REDZONE:
168 return "MallocRedZone";
169 case KASAN_KMEM_REDZONE:
170 return "KmemRedZone";
171 case KASAN_POOL_REDZONE:
172 return "PoolRedZone";
173 case KASAN_POOL_FREED:
174 return "PoolUseAfterFree";
175 case 1 ... 7:
176 return "RedZonePartial";
177 case KASAN_STACK_LEFT:
178 return "StackLeft";
179 case KASAN_STACK_RIGHT:
180 return "StackRight";
181 case KASAN_STACK_PARTIAL:
182 return "StackPartial";
183 case KASAN_USE_AFTER_SCOPE:
184 return "UseAfterScope";
185 default:
186 return "Unknown";
187 }
188 }
189
190 static void
191 kasan_report(unsigned long addr, size_t size, bool write, unsigned long pc,
192 uint8_t code)
193 {
194 REPORT("ASan: Unauthorized Access In %p: Addr %p [%zu byte%s, %s,"
195 " %s]\n",
196 (void *)pc, (void *)addr, size, (size > 1 ? "s" : ""),
197 (write ? "write" : "read"), kasan_code_name(code));
198 kasan_md_unwind();
199 }
200
201 static __always_inline void
202 kasan_shadow_1byte_markvalid(unsigned long addr)
203 {
204 int8_t *byte = kasan_md_addr_to_shad((void *)addr);
205 int8_t last = (addr & KASAN_SHADOW_MASK) + 1;
206
207 *byte = last;
208 }
209
210 static __always_inline void
211 kasan_shadow_Nbyte_markvalid(const void *addr, size_t size)
212 {
213 size_t i;
214
215 for (i = 0; i < size; i++) {
216 kasan_shadow_1byte_markvalid((unsigned long)addr+i);
217 }
218 }
219
220 static __always_inline void
221 kasan_shadow_Nbyte_fill(const void *addr, size_t size, uint8_t code)
222 {
223 void *shad;
224
225 if (__predict_false(size == 0))
226 return;
227 if (__predict_false(kasan_md_unsupported((vaddr_t)addr)))
228 return;
229
230 KASSERT((vaddr_t)addr % KASAN_SHADOW_SCALE_SIZE == 0);
231 KASSERT(size % KASAN_SHADOW_SCALE_SIZE == 0);
232
233 shad = (void *)kasan_md_addr_to_shad(addr);
234 size = size >> KASAN_SHADOW_SCALE_SHIFT;
235
236 __builtin_memset(shad, code, size);
237 }
238
239 void
240 kasan_add_redzone(size_t *size)
241 {
242 *size = roundup(*size, KASAN_SHADOW_SCALE_SIZE);
243 *size += KASAN_SHADOW_SCALE_SIZE;
244 }
245
246 void
247 kasan_softint(struct lwp *l)
248 {
249 const void *stk = (const void *)uvm_lwp_getuarea(l);
250
251 kasan_shadow_Nbyte_fill(stk, USPACE, 0);
252 }
253
254 /*
255 * In an area of size 'sz_with_redz', mark the 'size' first bytes as valid,
256 * and the rest as invalid. There are generally two use cases:
257 *
258 * o kasan_mark(addr, origsize, size, code), with origsize < size. This marks
259 * the redzone at the end of the buffer as invalid.
260 *
261 * o kasan_mark(addr, size, size, 0). This marks the entire buffer as valid.
262 */
263 void
264 kasan_mark(const void *addr, size_t size, size_t sz_with_redz, uint8_t code)
265 {
266 size_t i, n, redz;
267 int8_t *shad;
268
269 KASSERT((vaddr_t)addr % KASAN_SHADOW_SCALE_SIZE == 0);
270 redz = sz_with_redz - roundup(size, KASAN_SHADOW_SCALE_SIZE);
271 KASSERT(redz % KASAN_SHADOW_SCALE_SIZE == 0);
272 shad = kasan_md_addr_to_shad(addr);
273
274 /* Chunks of 8 bytes, valid. */
275 n = size / KASAN_SHADOW_SCALE_SIZE;
276 for (i = 0; i < n; i++) {
277 *shad++ = 0;
278 }
279
280 /* Possibly one chunk, mid. */
281 if ((size & KASAN_SHADOW_MASK) != 0) {
282 *shad++ = (size & KASAN_SHADOW_MASK);
283 }
284
285 /* Chunks of 8 bytes, invalid. */
286 n = redz / KASAN_SHADOW_SCALE_SIZE;
287 for (i = 0; i < n; i++) {
288 *shad++ = code;
289 }
290 }
291
292 /* -------------------------------------------------------------------------- */
293
294 #define ADDR_CROSSES_SCALE_BOUNDARY(addr, size) \
295 (addr >> KASAN_SHADOW_SCALE_SHIFT) != \
296 ((addr + size - 1) >> KASAN_SHADOW_SCALE_SHIFT)
297
298 static __always_inline bool
299 kasan_shadow_1byte_isvalid(unsigned long addr, uint8_t *code)
300 {
301 int8_t *byte = kasan_md_addr_to_shad((void *)addr);
302 int8_t last = (addr & KASAN_SHADOW_MASK) + 1;
303
304 if (__predict_true(*byte == 0 || last <= *byte)) {
305 return true;
306 }
307 *code = *byte;
308 return false;
309 }
310
311 static __always_inline bool
312 kasan_shadow_2byte_isvalid(unsigned long addr, uint8_t *code)
313 {
314 int8_t *byte, last;
315
316 if (ADDR_CROSSES_SCALE_BOUNDARY(addr, 2)) {
317 return (kasan_shadow_1byte_isvalid(addr, code) &&
318 kasan_shadow_1byte_isvalid(addr+1, code));
319 }
320
321 byte = kasan_md_addr_to_shad((void *)addr);
322 last = ((addr + 1) & KASAN_SHADOW_MASK) + 1;
323
324 if (__predict_true(*byte == 0 || last <= *byte)) {
325 return true;
326 }
327 *code = *byte;
328 return false;
329 }
330
331 static __always_inline bool
332 kasan_shadow_4byte_isvalid(unsigned long addr, uint8_t *code)
333 {
334 int8_t *byte, last;
335
336 if (ADDR_CROSSES_SCALE_BOUNDARY(addr, 4)) {
337 return (kasan_shadow_2byte_isvalid(addr, code) &&
338 kasan_shadow_2byte_isvalid(addr+2, code));
339 }
340
341 byte = kasan_md_addr_to_shad((void *)addr);
342 last = ((addr + 3) & KASAN_SHADOW_MASK) + 1;
343
344 if (__predict_true(*byte == 0 || last <= *byte)) {
345 return true;
346 }
347 *code = *byte;
348 return false;
349 }
350
351 static __always_inline bool
352 kasan_shadow_8byte_isvalid(unsigned long addr, uint8_t *code)
353 {
354 int8_t *byte, last;
355
356 if (ADDR_CROSSES_SCALE_BOUNDARY(addr, 8)) {
357 return (kasan_shadow_4byte_isvalid(addr, code) &&
358 kasan_shadow_4byte_isvalid(addr+4, code));
359 }
360
361 byte = kasan_md_addr_to_shad((void *)addr);
362 last = ((addr + 7) & KASAN_SHADOW_MASK) + 1;
363
364 if (__predict_true(*byte == 0 || last <= *byte)) {
365 return true;
366 }
367 *code = *byte;
368 return false;
369 }
370
371 static __always_inline bool
372 kasan_shadow_Nbyte_isvalid(unsigned long addr, size_t size, uint8_t *code)
373 {
374 size_t i;
375
376 for (i = 0; i < size; i++) {
377 if (!kasan_shadow_1byte_isvalid(addr+i, code))
378 return false;
379 }
380
381 return true;
382 }
383
384 static __always_inline void
385 kasan_shadow_check(unsigned long addr, size_t size, bool write,
386 unsigned long retaddr)
387 {
388 uint8_t code;
389 bool valid;
390
391 if (__predict_false(!kasan_enabled))
392 return;
393 if (__predict_false(size == 0))
394 return;
395 if (__predict_false(kasan_md_unsupported(addr)))
396 return;
397
398 if (__builtin_constant_p(size)) {
399 switch (size) {
400 case 1:
401 valid = kasan_shadow_1byte_isvalid(addr, &code);
402 break;
403 case 2:
404 valid = kasan_shadow_2byte_isvalid(addr, &code);
405 break;
406 case 4:
407 valid = kasan_shadow_4byte_isvalid(addr, &code);
408 break;
409 case 8:
410 valid = kasan_shadow_8byte_isvalid(addr, &code);
411 break;
412 default:
413 valid = kasan_shadow_Nbyte_isvalid(addr, size, &code);
414 break;
415 }
416 } else {
417 valid = kasan_shadow_Nbyte_isvalid(addr, size, &code);
418 }
419
420 if (__predict_false(!valid)) {
421 kasan_report(addr, size, write, retaddr, code);
422 }
423 }
424
425 /* -------------------------------------------------------------------------- */
426
427 void *
428 kasan_memcpy(void *dst, const void *src, size_t len)
429 {
430 kasan_shadow_check((unsigned long)src, len, false, __RET_ADDR);
431 kasan_shadow_check((unsigned long)dst, len, true, __RET_ADDR);
432 return __builtin_memcpy(dst, src, len);
433 }
434
435 int
436 kasan_memcmp(const void *b1, const void *b2, size_t len)
437 {
438 kasan_shadow_check((unsigned long)b1, len, false, __RET_ADDR);
439 kasan_shadow_check((unsigned long)b2, len, false, __RET_ADDR);
440 return __builtin_memcmp(b1, b2, len);
441 }
442
443 void *
444 kasan_memset(void *b, int c, size_t len)
445 {
446 kasan_shadow_check((unsigned long)b, len, true, __RET_ADDR);
447 return __builtin_memset(b, c, len);
448 }
449
450 void *
451 kasan_memmove(void *dst, const void *src, size_t len)
452 {
453 kasan_shadow_check((unsigned long)src, len, false, __RET_ADDR);
454 kasan_shadow_check((unsigned long)dst, len, true, __RET_ADDR);
455 return __builtin_memmove(dst, src, len);
456 }
457
458 char *
459 kasan_strcpy(char *dst, const char *src)
460 {
461 char *save = dst;
462
463 while (1) {
464 kasan_shadow_check((unsigned long)src, 1, false, __RET_ADDR);
465 kasan_shadow_check((unsigned long)dst, 1, true, __RET_ADDR);
466 *dst = *src;
467 if (*src == '\0')
468 break;
469 src++, dst++;
470 }
471
472 return save;
473 }
474
475 int
476 kasan_strcmp(const char *s1, const char *s2)
477 {
478 while (1) {
479 kasan_shadow_check((unsigned long)s1, 1, false, __RET_ADDR);
480 kasan_shadow_check((unsigned long)s2, 1, false, __RET_ADDR);
481 if (*s1 != *s2)
482 break;
483 if (*s1 == '\0')
484 return 0;
485 s1++, s2++;
486 }
487
488 return (*(const unsigned char *)s1 - *(const unsigned char *)s2);
489 }
490
491 size_t
492 kasan_strlen(const char *str)
493 {
494 const char *s;
495
496 s = str;
497 while (1) {
498 kasan_shadow_check((unsigned long)s, 1, false, __RET_ADDR);
499 if (*s == '\0')
500 break;
501 s++;
502 }
503
504 return (s - str);
505 }
506
507 #undef kcopy
508 #undef copystr
509 #undef copyinstr
510 #undef copyoutstr
511 #undef copyin
512
513 int kasan_kcopy(const void *, void *, size_t);
514 int kasan_copystr(const void *, void *, size_t, size_t *);
515 int kasan_copyinstr(const void *, void *, size_t, size_t *);
516 int kasan_copyoutstr(const void *, void *, size_t, size_t *);
517 int kasan_copyin(const void *, void *, size_t);
518 int kcopy(const void *, void *, size_t);
519 int copystr(const void *, void *, size_t, size_t *);
520 int copyinstr(const void *, void *, size_t, size_t *);
521 int copyoutstr(const void *, void *, size_t, size_t *);
522 int copyin(const void *, void *, size_t);
523
524 int
525 kasan_kcopy(const void *src, void *dst, size_t len)
526 {
527 kasan_shadow_check((unsigned long)src, len, false, __RET_ADDR);
528 kasan_shadow_check((unsigned long)dst, len, true, __RET_ADDR);
529 return kcopy(src, dst, len);
530 }
531
532 int
533 kasan_copystr(const void *kfaddr, void *kdaddr, size_t len, size_t *done)
534 {
535 kasan_shadow_check((unsigned long)kdaddr, len, true, __RET_ADDR);
536 return copystr(kfaddr, kdaddr, len, done);
537 }
538
539 int
540 kasan_copyin(const void *uaddr, void *kaddr, size_t len)
541 {
542 kasan_shadow_check((unsigned long)kaddr, len, true, __RET_ADDR);
543 return copyin(uaddr, kaddr, len);
544 }
545
546 int
547 kasan_copyinstr(const void *uaddr, void *kaddr, size_t len, size_t *done)
548 {
549 kasan_shadow_check((unsigned long)kaddr, len, true, __RET_ADDR);
550 return copyinstr(uaddr, kaddr, len, done);
551 }
552
553 int
554 kasan_copyoutstr(const void *kaddr, void *uaddr, size_t len, size_t *done)
555 {
556 kasan_shadow_check((unsigned long)kaddr, len, false, __RET_ADDR);
557 return copyoutstr(kaddr, uaddr, len, done);
558 }
559
560 /* -------------------------------------------------------------------------- */
561
562 #undef atomic_add_32
563 #undef atomic_add_int
564 #undef atomic_add_long
565 #undef atomic_add_ptr
566 #undef atomic_add_64
567 #undef atomic_add_32_nv
568 #undef atomic_add_int_nv
569 #undef atomic_add_long_nv
570 #undef atomic_add_ptr_nv
571 #undef atomic_add_64_nv
572 #undef atomic_and_32
573 #undef atomic_and_uint
574 #undef atomic_and_ulong
575 #undef atomic_and_64
576 #undef atomic_and_32_nv
577 #undef atomic_and_uint_nv
578 #undef atomic_and_ulong_nv
579 #undef atomic_and_64_nv
580 #undef atomic_or_32
581 #undef atomic_or_uint
582 #undef atomic_or_ulong
583 #undef atomic_or_64
584 #undef atomic_or_32_nv
585 #undef atomic_or_uint_nv
586 #undef atomic_or_ulong_nv
587 #undef atomic_or_64_nv
588 #undef atomic_cas_32
589 #undef atomic_cas_uint
590 #undef atomic_cas_ulong
591 #undef atomic_cas_ptr
592 #undef atomic_cas_64
593 #undef atomic_cas_32_ni
594 #undef atomic_cas_uint_ni
595 #undef atomic_cas_ulong_ni
596 #undef atomic_cas_ptr_ni
597 #undef atomic_cas_64_ni
598 #undef atomic_swap_32
599 #undef atomic_swap_uint
600 #undef atomic_swap_ulong
601 #undef atomic_swap_ptr
602 #undef atomic_swap_64
603 #undef atomic_dec_32
604 #undef atomic_dec_uint
605 #undef atomic_dec_ulong
606 #undef atomic_dec_ptr
607 #undef atomic_dec_64
608 #undef atomic_dec_32_nv
609 #undef atomic_dec_uint_nv
610 #undef atomic_dec_ulong_nv
611 #undef atomic_dec_ptr_nv
612 #undef atomic_dec_64_nv
613 #undef atomic_inc_32
614 #undef atomic_inc_uint
615 #undef atomic_inc_ulong
616 #undef atomic_inc_ptr
617 #undef atomic_inc_64
618 #undef atomic_inc_32_nv
619 #undef atomic_inc_uint_nv
620 #undef atomic_inc_ulong_nv
621 #undef atomic_inc_ptr_nv
622 #undef atomic_inc_64_nv
623
624 #define ASAN_ATOMIC_FUNC_ADD(name, tret, targ1, targ2) \
625 void atomic_add_##name(volatile targ1 *, targ2); \
626 void kasan_atomic_add_##name(volatile targ1 *, targ2); \
627 void kasan_atomic_add_##name(volatile targ1 *ptr, targ2 val) \
628 { \
629 kasan_shadow_check((uintptr_t)ptr, sizeof(tret), true, \
630 __RET_ADDR); \
631 atomic_add_##name(ptr, val); \
632 } \
633 tret atomic_add_##name##_nv(volatile targ1 *, targ2); \
634 tret kasan_atomic_add_##name##_nv(volatile targ1 *, targ2); \
635 tret kasan_atomic_add_##name##_nv(volatile targ1 *ptr, targ2 val) \
636 { \
637 kasan_shadow_check((uintptr_t)ptr, sizeof(tret), true, \
638 __RET_ADDR); \
639 return atomic_add_##name##_nv(ptr, val); \
640 }
641
642 #define ASAN_ATOMIC_FUNC_AND(name, tret, targ1, targ2) \
643 void atomic_and_##name(volatile targ1 *, targ2); \
644 void kasan_atomic_and_##name(volatile targ1 *, targ2); \
645 void kasan_atomic_and_##name(volatile targ1 *ptr, targ2 val) \
646 { \
647 kasan_shadow_check((uintptr_t)ptr, sizeof(tret), true, \
648 __RET_ADDR); \
649 atomic_and_##name(ptr, val); \
650 } \
651 tret atomic_and_##name##_nv(volatile targ1 *, targ2); \
652 tret kasan_atomic_and_##name##_nv(volatile targ1 *, targ2); \
653 tret kasan_atomic_and_##name##_nv(volatile targ1 *ptr, targ2 val) \
654 { \
655 kasan_shadow_check((uintptr_t)ptr, sizeof(tret), true, \
656 __RET_ADDR); \
657 return atomic_and_##name##_nv(ptr, val); \
658 }
659
660 #define ASAN_ATOMIC_FUNC_OR(name, tret, targ1, targ2) \
661 void atomic_or_##name(volatile targ1 *, targ2); \
662 void kasan_atomic_or_##name(volatile targ1 *, targ2); \
663 void kasan_atomic_or_##name(volatile targ1 *ptr, targ2 val) \
664 { \
665 kasan_shadow_check((uintptr_t)ptr, sizeof(tret), true, \
666 __RET_ADDR); \
667 atomic_or_##name(ptr, val); \
668 } \
669 tret atomic_or_##name##_nv(volatile targ1 *, targ2); \
670 tret kasan_atomic_or_##name##_nv(volatile targ1 *, targ2); \
671 tret kasan_atomic_or_##name##_nv(volatile targ1 *ptr, targ2 val) \
672 { \
673 kasan_shadow_check((uintptr_t)ptr, sizeof(tret), true, \
674 __RET_ADDR); \
675 return atomic_or_##name##_nv(ptr, val); \
676 }
677
678 #define ASAN_ATOMIC_FUNC_CAS(name, tret, targ1, targ2) \
679 tret atomic_cas_##name(volatile targ1 *, targ2, targ2); \
680 tret kasan_atomic_cas_##name(volatile targ1 *, targ2, targ2); \
681 tret kasan_atomic_cas_##name(volatile targ1 *ptr, targ2 exp, targ2 new) \
682 { \
683 kasan_shadow_check((uintptr_t)ptr, sizeof(tret), true, \
684 __RET_ADDR); \
685 return atomic_cas_##name(ptr, exp, new); \
686 } \
687 tret atomic_cas_##name##_ni(volatile targ1 *, targ2, targ2); \
688 tret kasan_atomic_cas_##name##_ni(volatile targ1 *, targ2, targ2); \
689 tret kasan_atomic_cas_##name##_ni(volatile targ1 *ptr, targ2 exp, targ2 new) \
690 { \
691 kasan_shadow_check((uintptr_t)ptr, sizeof(tret), true, \
692 __RET_ADDR); \
693 return atomic_cas_##name##_ni(ptr, exp, new); \
694 }
695
696 #define ASAN_ATOMIC_FUNC_SWAP(name, tret, targ1, targ2) \
697 tret atomic_swap_##name(volatile targ1 *, targ2); \
698 tret kasan_atomic_swap_##name(volatile targ1 *, targ2); \
699 tret kasan_atomic_swap_##name(volatile targ1 *ptr, targ2 val) \
700 { \
701 kasan_shadow_check((uintptr_t)ptr, sizeof(tret), true, \
702 __RET_ADDR); \
703 return atomic_swap_##name(ptr, val); \
704 }
705
706 #define ASAN_ATOMIC_FUNC_DEC(name, tret, targ1) \
707 void atomic_dec_##name(volatile targ1 *); \
708 void kasan_atomic_dec_##name(volatile targ1 *); \
709 void kasan_atomic_dec_##name(volatile targ1 *ptr) \
710 { \
711 kasan_shadow_check((uintptr_t)ptr, sizeof(tret), true, \
712 __RET_ADDR); \
713 atomic_dec_##name(ptr); \
714 } \
715 tret atomic_dec_##name##_nv(volatile targ1 *); \
716 tret kasan_atomic_dec_##name##_nv(volatile targ1 *); \
717 tret kasan_atomic_dec_##name##_nv(volatile targ1 *ptr) \
718 { \
719 kasan_shadow_check((uintptr_t)ptr, sizeof(tret), true, \
720 __RET_ADDR); \
721 return atomic_dec_##name##_nv(ptr); \
722 }
723
724 #define ASAN_ATOMIC_FUNC_INC(name, tret, targ1) \
725 void atomic_inc_##name(volatile targ1 *); \
726 void kasan_atomic_inc_##name(volatile targ1 *); \
727 void kasan_atomic_inc_##name(volatile targ1 *ptr) \
728 { \
729 kasan_shadow_check((uintptr_t)ptr, sizeof(tret), true, \
730 __RET_ADDR); \
731 atomic_inc_##name(ptr); \
732 } \
733 tret atomic_inc_##name##_nv(volatile targ1 *); \
734 tret kasan_atomic_inc_##name##_nv(volatile targ1 *); \
735 tret kasan_atomic_inc_##name##_nv(volatile targ1 *ptr) \
736 { \
737 kasan_shadow_check((uintptr_t)ptr, sizeof(tret), true, \
738 __RET_ADDR); \
739 return atomic_inc_##name##_nv(ptr); \
740 }
741
742 ASAN_ATOMIC_FUNC_ADD(32, uint32_t, uint32_t, int32_t);
743 ASAN_ATOMIC_FUNC_ADD(64, uint64_t, uint64_t, int64_t);
744 ASAN_ATOMIC_FUNC_ADD(int, unsigned int, unsigned int, int);
745 ASAN_ATOMIC_FUNC_ADD(long, unsigned long, unsigned long, long);
746 ASAN_ATOMIC_FUNC_ADD(ptr, void *, void, ssize_t);
747
748 ASAN_ATOMIC_FUNC_AND(32, uint32_t, uint32_t, uint32_t);
749 ASAN_ATOMIC_FUNC_AND(64, uint64_t, uint64_t, uint64_t);
750 ASAN_ATOMIC_FUNC_AND(uint, unsigned int, unsigned int, unsigned int);
751 ASAN_ATOMIC_FUNC_AND(ulong, unsigned long, unsigned long, unsigned long);
752
753 ASAN_ATOMIC_FUNC_OR(32, uint32_t, uint32_t, uint32_t);
754 ASAN_ATOMIC_FUNC_OR(64, uint64_t, uint64_t, uint64_t);
755 ASAN_ATOMIC_FUNC_OR(uint, unsigned int, unsigned int, unsigned int);
756 ASAN_ATOMIC_FUNC_OR(ulong, unsigned long, unsigned long, unsigned long);
757
758 ASAN_ATOMIC_FUNC_CAS(32, uint32_t, uint32_t, uint32_t);
759 ASAN_ATOMIC_FUNC_CAS(64, uint64_t, uint64_t, uint64_t);
760 ASAN_ATOMIC_FUNC_CAS(uint, unsigned int, unsigned int, unsigned int);
761 ASAN_ATOMIC_FUNC_CAS(ulong, unsigned long, unsigned long, unsigned long);
762 ASAN_ATOMIC_FUNC_CAS(ptr, void *, void, void *);
763
764 ASAN_ATOMIC_FUNC_SWAP(32, uint32_t, uint32_t, uint32_t);
765 ASAN_ATOMIC_FUNC_SWAP(64, uint64_t, uint64_t, uint64_t);
766 ASAN_ATOMIC_FUNC_SWAP(uint, unsigned int, unsigned int, unsigned int);
767 ASAN_ATOMIC_FUNC_SWAP(ulong, unsigned long, unsigned long, unsigned long);
768 ASAN_ATOMIC_FUNC_SWAP(ptr, void *, void, void *);
769
770 ASAN_ATOMIC_FUNC_DEC(32, uint32_t, uint32_t)
771 ASAN_ATOMIC_FUNC_DEC(64, uint64_t, uint64_t)
772 ASAN_ATOMIC_FUNC_DEC(uint, unsigned int, unsigned int);
773 ASAN_ATOMIC_FUNC_DEC(ulong, unsigned long, unsigned long);
774 ASAN_ATOMIC_FUNC_DEC(ptr, void *, void);
775
776 ASAN_ATOMIC_FUNC_INC(32, uint32_t, uint32_t)
777 ASAN_ATOMIC_FUNC_INC(64, uint64_t, uint64_t)
778 ASAN_ATOMIC_FUNC_INC(uint, unsigned int, unsigned int);
779 ASAN_ATOMIC_FUNC_INC(ulong, unsigned long, unsigned long);
780 ASAN_ATOMIC_FUNC_INC(ptr, void *, void);
781
782 /* -------------------------------------------------------------------------- */
783
784 #ifdef __HAVE_KASAN_INSTR_BUS
785
786 #include <sys/bus.h>
787
788 #undef bus_space_read_multi_1
789 #undef bus_space_read_multi_2
790 #undef bus_space_read_multi_4
791 #undef bus_space_read_multi_8
792 #undef bus_space_read_multi_stream_1
793 #undef bus_space_read_multi_stream_2
794 #undef bus_space_read_multi_stream_4
795 #undef bus_space_read_multi_stream_8
796 #undef bus_space_read_region_1
797 #undef bus_space_read_region_2
798 #undef bus_space_read_region_4
799 #undef bus_space_read_region_8
800 #undef bus_space_read_region_stream_1
801 #undef bus_space_read_region_stream_2
802 #undef bus_space_read_region_stream_4
803 #undef bus_space_read_region_stream_8
804 #undef bus_space_write_multi_1
805 #undef bus_space_write_multi_2
806 #undef bus_space_write_multi_4
807 #undef bus_space_write_multi_8
808 #undef bus_space_write_multi_stream_1
809 #undef bus_space_write_multi_stream_2
810 #undef bus_space_write_multi_stream_4
811 #undef bus_space_write_multi_stream_8
812 #undef bus_space_write_region_1
813 #undef bus_space_write_region_2
814 #undef bus_space_write_region_4
815 #undef bus_space_write_region_8
816 #undef bus_space_write_region_stream_1
817 #undef bus_space_write_region_stream_2
818 #undef bus_space_write_region_stream_4
819 #undef bus_space_write_region_stream_8
820
821 #define ASAN_BUS_READ_FUNC(bytes, bits) \
822 void bus_space_read_multi_##bytes(bus_space_tag_t, bus_space_handle_t, \
823 bus_size_t, uint##bits##_t *, bus_size_t); \
824 void kasan_bus_space_read_multi_##bytes(bus_space_tag_t, \
825 bus_space_handle_t, bus_size_t, uint##bits##_t *, bus_size_t); \
826 void kasan_bus_space_read_multi_##bytes(bus_space_tag_t tag, \
827 bus_space_handle_t hnd, bus_size_t size, uint##bits##_t *buf, \
828 bus_size_t count) \
829 { \
830 kasan_shadow_check((uintptr_t)buf, \
831 sizeof(uint##bits##_t) * count, false, __RET_ADDR); \
832 bus_space_read_multi_##bytes(tag, hnd, size, buf, count); \
833 } \
834 void bus_space_read_multi_stream_##bytes(bus_space_tag_t, \
835 bus_space_handle_t, bus_size_t, uint##bits##_t *, bus_size_t); \
836 void kasan_bus_space_read_multi_stream_##bytes(bus_space_tag_t, \
837 bus_space_handle_t, bus_size_t, uint##bits##_t *, bus_size_t); \
838 void kasan_bus_space_read_multi_stream_##bytes(bus_space_tag_t tag, \
839 bus_space_handle_t hnd, bus_size_t size, uint##bits##_t *buf, \
840 bus_size_t count) \
841 { \
842 kasan_shadow_check((uintptr_t)buf, \
843 sizeof(uint##bits##_t) * count, false, __RET_ADDR); \
844 bus_space_read_multi_stream_##bytes(tag, hnd, size, buf, count);\
845 } \
846 void bus_space_read_region_##bytes(bus_space_tag_t, bus_space_handle_t, \
847 bus_size_t, uint##bits##_t *, bus_size_t); \
848 void kasan_bus_space_read_region_##bytes(bus_space_tag_t, \
849 bus_space_handle_t, bus_size_t, uint##bits##_t *, bus_size_t); \
850 void kasan_bus_space_read_region_##bytes(bus_space_tag_t tag, \
851 bus_space_handle_t hnd, bus_size_t size, uint##bits##_t *buf, \
852 bus_size_t count) \
853 { \
854 kasan_shadow_check((uintptr_t)buf, \
855 sizeof(uint##bits##_t) * count, false, __RET_ADDR); \
856 bus_space_read_region_##bytes(tag, hnd, size, buf, count); \
857 } \
858 void bus_space_read_region_stream_##bytes(bus_space_tag_t, \
859 bus_space_handle_t, bus_size_t, uint##bits##_t *, bus_size_t); \
860 void kasan_bus_space_read_region_stream_##bytes(bus_space_tag_t, \
861 bus_space_handle_t, bus_size_t, uint##bits##_t *, bus_size_t); \
862 void kasan_bus_space_read_region_stream_##bytes(bus_space_tag_t tag, \
863 bus_space_handle_t hnd, bus_size_t size, uint##bits##_t *buf, \
864 bus_size_t count) \
865 { \
866 kasan_shadow_check((uintptr_t)buf, \
867 sizeof(uint##bits##_t) * count, false, __RET_ADDR); \
868 bus_space_read_region_stream_##bytes(tag, hnd, size, buf, count);\
869 }
870
871 #define ASAN_BUS_WRITE_FUNC(bytes, bits) \
872 void bus_space_write_multi_##bytes(bus_space_tag_t, bus_space_handle_t, \
873 bus_size_t, const uint##bits##_t *, bus_size_t); \
874 void kasan_bus_space_write_multi_##bytes(bus_space_tag_t, \
875 bus_space_handle_t, bus_size_t, const uint##bits##_t *, bus_size_t);\
876 void kasan_bus_space_write_multi_##bytes(bus_space_tag_t tag, \
877 bus_space_handle_t hnd, bus_size_t size, const uint##bits##_t *buf, \
878 bus_size_t count) \
879 { \
880 kasan_shadow_check((uintptr_t)buf, \
881 sizeof(uint##bits##_t) * count, true, __RET_ADDR); \
882 bus_space_write_multi_##bytes(tag, hnd, size, buf, count); \
883 } \
884 void bus_space_write_multi_stream_##bytes(bus_space_tag_t, \
885 bus_space_handle_t, bus_size_t, const uint##bits##_t *, bus_size_t);\
886 void kasan_bus_space_write_multi_stream_##bytes(bus_space_tag_t, \
887 bus_space_handle_t, bus_size_t, const uint##bits##_t *, bus_size_t);\
888 void kasan_bus_space_write_multi_stream_##bytes(bus_space_tag_t tag, \
889 bus_space_handle_t hnd, bus_size_t size, const uint##bits##_t *buf, \
890 bus_size_t count) \
891 { \
892 kasan_shadow_check((uintptr_t)buf, \
893 sizeof(uint##bits##_t) * count, true, __RET_ADDR); \
894 bus_space_write_multi_stream_##bytes(tag, hnd, size, buf, count);\
895 } \
896 void bus_space_write_region_##bytes(bus_space_tag_t, bus_space_handle_t,\
897 bus_size_t, const uint##bits##_t *, bus_size_t); \
898 void kasan_bus_space_write_region_##bytes(bus_space_tag_t, \
899 bus_space_handle_t, bus_size_t, const uint##bits##_t *, bus_size_t);\
900 void kasan_bus_space_write_region_##bytes(bus_space_tag_t tag, \
901 bus_space_handle_t hnd, bus_size_t size, const uint##bits##_t *buf, \
902 bus_size_t count) \
903 { \
904 kasan_shadow_check((uintptr_t)buf, \
905 sizeof(uint##bits##_t) * count, true, __RET_ADDR); \
906 bus_space_write_region_##bytes(tag, hnd, size, buf, count); \
907 } \
908 void bus_space_write_region_stream_##bytes(bus_space_tag_t, \
909 bus_space_handle_t, bus_size_t, const uint##bits##_t *, bus_size_t);\
910 void kasan_bus_space_write_region_stream_##bytes(bus_space_tag_t, \
911 bus_space_handle_t, bus_size_t, const uint##bits##_t *, bus_size_t);\
912 void kasan_bus_space_write_region_stream_##bytes(bus_space_tag_t tag, \
913 bus_space_handle_t hnd, bus_size_t size, const uint##bits##_t *buf, \
914 bus_size_t count) \
915 { \
916 kasan_shadow_check((uintptr_t)buf, \
917 sizeof(uint##bits##_t) * count, true, __RET_ADDR); \
918 bus_space_write_region_stream_##bytes(tag, hnd, size, buf, count);\
919 }
920
921 ASAN_BUS_READ_FUNC(1, 8)
922 ASAN_BUS_READ_FUNC(2, 16)
923 ASAN_BUS_READ_FUNC(4, 32)
924 ASAN_BUS_READ_FUNC(8, 64)
925
926 ASAN_BUS_WRITE_FUNC(1, 8)
927 ASAN_BUS_WRITE_FUNC(2, 16)
928 ASAN_BUS_WRITE_FUNC(4, 32)
929 ASAN_BUS_WRITE_FUNC(8, 64)
930
931 #endif /* __HAVE_KASAN_INSTR_BUS */
932
933 /* -------------------------------------------------------------------------- */
934
935 #ifdef __HAVE_KASAN_INSTR_DMA
936
937 #include <sys/mbuf.h>
938
939 static void
940 kasan_dma_sync_linear(uint8_t *buf, bus_addr_t offset, bus_size_t len,
941 bool write, uintptr_t pc)
942 {
943 kasan_shadow_check((uintptr_t)(buf + offset), len, write, pc);
944 }
945
946 static void
947 kasan_dma_sync_mbuf(struct mbuf *m, bus_addr_t offset, bus_size_t len,
948 bool write, uintptr_t pc)
949 {
950 bus_addr_t minlen;
951
952 for (; m != NULL && len != 0; m = m->m_next) {
953 kasan_shadow_check((uintptr_t)m, sizeof(*m), false, pc);
954
955 if (offset >= m->m_len) {
956 offset -= m->m_len;
957 continue;
958 }
959
960 minlen = MIN(len, m->m_len - offset);
961 kasan_shadow_check((uintptr_t)(mtod(m, char *) + offset),
962 minlen, write, pc);
963
964 offset = 0;
965 len -= minlen;
966 }
967 }
968
969 static void
970 kasan_dma_sync_uio(struct uio *uio, bus_addr_t offset, bus_size_t len,
971 bool write, uintptr_t pc)
972 {
973 bus_size_t minlen, resid;
974 struct iovec *iov;
975 int i;
976
977 if (uio->uio_vmspace != NULL)
978 return;
979
980 kasan_shadow_check((uintptr_t)uio, sizeof(struct uio), false, pc);
981
982 resid = uio->uio_resid;
983 iov = uio->uio_iov;
984
985 for (i = 0; i < uio->uio_iovcnt && resid != 0; i++) {
986 kasan_shadow_check((uintptr_t)&iov[i], sizeof(iov[i]),
987 false, pc);
988 minlen = MIN(resid, iov[i].iov_len);
989 kasan_shadow_check((uintptr_t)iov[i].iov_base, minlen,
990 write, pc);
991 resid -= minlen;
992 }
993 }
994
995 void
996 kasan_dma_sync(bus_dmamap_t map, bus_addr_t offset, bus_size_t len, int ops)
997 {
998 bool write = (ops & (BUS_DMASYNC_PREWRITE|BUS_DMASYNC_POSTWRITE)) != 0;
999
1000 switch (map->dm_buftype) {
1001 case KASAN_DMA_LINEAR:
1002 kasan_dma_sync_linear(map->dm_buf, offset, len, write,
1003 __RET_ADDR);
1004 break;
1005 case KASAN_DMA_MBUF:
1006 kasan_dma_sync_mbuf(map->dm_buf, offset, len, write,
1007 __RET_ADDR);
1008 break;
1009 case KASAN_DMA_UIO:
1010 kasan_dma_sync_uio(map->dm_buf, offset, len, write,
1011 __RET_ADDR);
1012 break;
1013 case KASAN_DMA_RAW:
1014 break;
1015 default:
1016 panic("%s: impossible", __func__);
1017 }
1018 }
1019
1020 void
1021 kasan_dma_load(bus_dmamap_t map, void *buf, bus_size_t buflen, int type)
1022 {
1023 map->dm_buf = buf;
1024 map->dm_buflen = buflen;
1025 map->dm_buftype = type;
1026 }
1027
1028 #endif /* __HAVE_KASAN_INSTR_DMA */
1029
1030 /* -------------------------------------------------------------------------- */
1031
1032 void __asan_register_globals(struct __asan_global *, size_t);
1033 void __asan_unregister_globals(struct __asan_global *, size_t);
1034
1035 void
1036 __asan_register_globals(struct __asan_global *globals, size_t n)
1037 {
1038 size_t i;
1039
1040 for (i = 0; i < n; i++) {
1041 kasan_mark(globals[i].beg, globals[i].size,
1042 globals[i].size_with_redzone, KASAN_GENERIC_REDZONE);
1043 }
1044 }
1045
1046 void
1047 __asan_unregister_globals(struct __asan_global *globals, size_t n)
1048 {
1049 /* never called */
1050 }
1051
1052 #define ASAN_LOAD_STORE(size) \
1053 void __asan_load##size(unsigned long); \
1054 void __asan_load##size(unsigned long addr) \
1055 { \
1056 kasan_shadow_check(addr, size, false, __RET_ADDR);\
1057 } \
1058 void __asan_load##size##_noabort(unsigned long); \
1059 void __asan_load##size##_noabort(unsigned long addr) \
1060 { \
1061 kasan_shadow_check(addr, size, false, __RET_ADDR);\
1062 } \
1063 void __asan_store##size(unsigned long); \
1064 void __asan_store##size(unsigned long addr) \
1065 { \
1066 kasan_shadow_check(addr, size, true, __RET_ADDR);\
1067 } \
1068 void __asan_store##size##_noabort(unsigned long); \
1069 void __asan_store##size##_noabort(unsigned long addr) \
1070 { \
1071 kasan_shadow_check(addr, size, true, __RET_ADDR);\
1072 }
1073
1074 ASAN_LOAD_STORE(1);
1075 ASAN_LOAD_STORE(2);
1076 ASAN_LOAD_STORE(4);
1077 ASAN_LOAD_STORE(8);
1078 ASAN_LOAD_STORE(16);
1079
1080 void __asan_loadN(unsigned long, size_t);
1081 void __asan_loadN_noabort(unsigned long, size_t);
1082 void __asan_storeN(unsigned long, size_t);
1083 void __asan_storeN_noabort(unsigned long, size_t);
1084 void __asan_handle_no_return(void);
1085
1086 void
1087 __asan_loadN(unsigned long addr, size_t size)
1088 {
1089 kasan_shadow_check(addr, size, false, __RET_ADDR);
1090 }
1091
1092 void
1093 __asan_loadN_noabort(unsigned long addr, size_t size)
1094 {
1095 kasan_shadow_check(addr, size, false, __RET_ADDR);
1096 }
1097
1098 void
1099 __asan_storeN(unsigned long addr, size_t size)
1100 {
1101 kasan_shadow_check(addr, size, true, __RET_ADDR);
1102 }
1103
1104 void
1105 __asan_storeN_noabort(unsigned long addr, size_t size)
1106 {
1107 kasan_shadow_check(addr, size, true, __RET_ADDR);
1108 }
1109
1110 void
1111 __asan_handle_no_return(void)
1112 {
1113 /* nothing */
1114 }
1115
1116 #define ASAN_SET_SHADOW(byte) \
1117 void __asan_set_shadow_##byte(void *, size_t); \
1118 void __asan_set_shadow_##byte(void *addr, size_t size) \
1119 { \
1120 __builtin_memset((void *)addr, 0x##byte, size); \
1121 }
1122
1123 ASAN_SET_SHADOW(00);
1124 ASAN_SET_SHADOW(f1);
1125 ASAN_SET_SHADOW(f2);
1126 ASAN_SET_SHADOW(f3);
1127 ASAN_SET_SHADOW(f5);
1128 ASAN_SET_SHADOW(f8);
1129
1130 void __asan_poison_stack_memory(const void *, size_t);
1131 void __asan_unpoison_stack_memory(const void *, size_t);
1132
1133 void __asan_poison_stack_memory(const void *addr, size_t size)
1134 {
1135 size = roundup(size, KASAN_SHADOW_SCALE_SIZE);
1136 kasan_shadow_Nbyte_fill(addr, size, KASAN_USE_AFTER_SCOPE);
1137 }
1138
1139 void __asan_unpoison_stack_memory(const void *addr, size_t size)
1140 {
1141 kasan_shadow_Nbyte_markvalid(addr, size);
1142 }
1143